Egypt's data localisation requirements have been extended to cover fintech operators, requiring that customer data generated within the country be stored on infrastructure located within it. The policy is a sovereignty decision, and the reasoning behind it is intelligible. The trade-offs it produces are now becoming visible.
The case for localisation is control: a regulator that can reach the data, the servers, and the operators within its own jurisdiction can enforce its rules. Data held abroad is data held beyond the practical reach of domestic law. For a regulator that has seen fintech operators scale across borders and then become difficult to supervise, the instinct to keep the data at home is reasonable.
